Impact
A flaw in Oracle Hyperion Data Relationship Management's access and security component allows an unauthenticated attacker with network access via HTTP to create, delete or modify critical data or to obtain unauthorized control over all data accessible to the product. This vulnerability is an example of CWE-284 (Improper Access Control), enabling attackers to compromise data confidentiality and integrity without credentials.
Affected Systems
Oracle Corporation's Hyperion Data Relationship Management version 11.2.25.0.000 is the sole publicly identified vulnerable release.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 reflects a high impact on confidentiality and integrity, while the EPSS score of less than 1% shows a low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. The attacker requires only network access to an HTTP endpoint; no authentication or privileged credentials are needed, implying that any network-connected attacker could potentially compromise all data managed by Hyperion.
OpenCVE Enrichment